In the fortiAnalyzer FortiView, sourse an destination IP addresse from FortiGate devices are not resolving to a hostname How can you resolve the sourse and destination IP addresses, whhout introducing any additional ´performance impact to FortiAnayzer
configure local DNS servers on FortiAnalyzer
Configure # set resolve-ip enable in the system ForWiew settigs
resolve IP addresses on FortiGate
Resolve IP addresses on a per-Adom basis to reduce delay on fortiView while IPs resolve
If a hard disk fails on a FortiAnalyzer that supports software RAID, what should you do to bring the FortiAnalyzer back to functioning normally, whithout losing data?
Take no action if the RAID level supports a failed disk
Replace the disk and rebuild the RAID manually
Shut down FortiAnalyzer and replace the disk
Hot swap the disk
How are logs forwarded when FortiAnalyzer is configured to use aggregaton mode?
Logs and content files are stored and uploaded at a scheduled time
Log san content files are forwarded as they are received
Logs are forwarded as they are received, and content files are uploaded at a scheduled time
Logs are forwarded as they are received
For which two SAML roles can the FortiAnalyzer be confogured? (Choose two)
Service provider
Prinicpal
Identity provider
Identity collector
In order for FortiAnalyzer to collect logs from a FortiGate device, which two configurations are required? (Choose two)
FortiGate must be registered whit FortiAnalyzer
ADOMs must be enabled
Remote logging must be enabled on FortiGate
Log encryption must be enabled
Refer to the exhibit
What does the 1000 MB máximum for disk utilization refer to?
The disk quota for each device in the ADOM
The disk quota for the ADOM type
The disk quota for all devices in the ADOM
The disk quota for the FortiAnalyzer model
Which FortiAnalyzer feature allows you to retrieve the archived logs matching a specific timeframe from anoter FortiAnalyzer device?
Log upload
Indicators of Compromise
Log forwarding an aggregation mode
Log fetching
What happens when a log file saved on FortiAnalyzer disks reaches the size specified in the device log settings?
The log file is stored as a raw log and is available for analytic support.
The log file rolls over and is archived.
The log file is purged from the database
The log file is overwritten
Which two constraints cam impact the amount of reserved disk space required by FortiAnalyzer? (Choose two)
RAID level
License type
Disk size
Total quota
View the exhibit.
What does the data point at 14:35 tell you?
FortiAnalyzer is dropping logs.
FortiAnalyzer is indexing logs faster than logs are being received.
FortiAnalyzer has temporarily stopped receiving logs so older logs’ can be indexed
The sqlplugind daemon is ahead in indexing by one log.
Which two methods can you use to send event notifications when an event occurs that matches a configured event handler?(Choose two)
SNMP
SMS
IM
Email
Which FortiGate process caches logs when FortiAnalyzer is not reachable?
logfiled
miglogd
oftpd
sqlplugind
What is the purpose of a predefined template on the FortiAnalyzer?
It specifies report settings which contains time period, device selection, and Schedule
it contains predefined data to generate mock reports
It specifies the report layout which contains predefined texts, charts, and macros
It can be edited and modified as required
When you perform a system backup, what does the backup configuration contain? (Choose two)
Authorized devices logs
Generated reports
Device list
System information
If you upgrade the FortiAnalyzer firmware, which report element can be affected?
Report scheduling
Output profiles
Report settings
Custom datases
Ont the RAID management page, the disk status is listed as initializing What does the status initializing indicate about what the FortiAnalyzer is currebtly doing?
FortiAnalyzer is writing to all of its hard drives to make the array fault tolerant
FortiAnalyzer is functioning normally
FortiAnalyzer is writing data to a newly added hard drive to restore it to an optimal state
FortiAnalyzer is ensuring that the party data of a redundant drive is valid
What are two advantages of setting up fabric ADOM? (choose two)
It can include all Fortinet devices that are part of the same Security Fabric
It can include only Fortigate devices that are part of the same Security Fabric
It can be used to facilitate communication between devices in same Security Fabric
It can be used for fast data processing and log correlation
Why is the total quota less than the total system storage?
The oftpd process has not archived the logs yet
The logfiled process is just estimating the total quota
Some space is reserved for system use
3.6% of the system storage is already being used
What is the main purpose of us4ng an NTP server on FortiAnalyzer and all of its registered devices?
Host name resolution
Log collection
Real-time forwarding
Log correlation
You have moved a registered logging device out of one ADOM and into a new ADOM. What happens when you rebuild the new ADOM database?
FortiAnaIy‹er resets the disk quota of the new ADOM to default.
FortiAnalyzer migrates analytics logs to the new ADOM.
FartiAnalyzer removes analytics logs from the old ADOM
FortiAnaIy‹er migrates archive logs to the new ADOM
Which two purposes does the auto cache setting on reports serve? (Choose two.)
It automatically updates the hcache when new logs arrive.
It provides diagnostics on report generation time.
It reduces the log insert lag rate.
It reduced report generation time.
How does FortiAnalyZer retrieve specific log data from the database?
SQL SELECT statement
SQL GET statement
SQL EXTRACT statement
SQL FROM statement
FortiAnalyzer uses the Optimized Fabric Transfer Protocol (OFTP} over SSL for which purpose?
To send an identical set of lags to a second logging server
To upload logs to an SFTP server
To prevent log modification during backup
To encrypt log communication between devices
Which two statements about leg forwarding are true? (Choose two)
Forwarded logo cannot be filtered to match specific criteria.
The client retains a local copy of the logs after forwardlng.
Logs are forwarded in real-time only.
You can use aggregation mode only with another FortiAnalyzer
Consider the CLI command:
#configure system global set log-checksum md5 end
What is the purpose of the command ?
To add a unique tag to each log to prove that it came from this FortiAnalyzer
To encrypt Iog communicatons.
To add a log file checksum.
To add the MDS hash value and authentication code
What is the purpose of employing RAID with FortiAnalyzer?
To introduce redundancy to your log data
To provide data separation between ADOMs
To separate analytical and archive data
To back up your logs
What is the recommended method of expanding disk space on a FortiAnalyzer VM?
From the VM host manager, add an additional virtual disk and use the #execute lvm extend <disk number> command to expand the storage
From the VM host manager, expand the size of the existing virtual disk
From the VM host manager, expand the size of the existing virtual disk and use the # execute format disk command to reformat the dlsk
From the VM host manager, add an additional disk and rebuild your RAID array
How do you restrict an administrator’s access to a subset of your organization’s ADOMs?
Set the ADOM mode to Advanced
Assign the ADOMs to the administrator’s account
Configure trusted hosts
Assign the default Super User administrator profile
What can the CLI command # diagnose test application oftpd 3 help you to determine?
What devices and IP addresses are connecting to FortiAnalyzer
What logs, if any, are reaching FortiAnalyzer
What ADOMs are enabled and configured
What devices are registered and unregistered
What FortfView tool can you use to automatically build a dataset and chart based on a filtered search result?
Chart Builder
Export to Report Chart
Dataset Library
Custom View
What must you configure on FortiAnalyzer to upload a FortiAnalyzer report to a supported external Server? (Choose two.)
SFTP, FTP, or SCP server
Mail server
Output profile
Logs are being deleted from one of your ADOMs earlier than the configured setting for archiving in your data policy. What is the most likely problem?
The total disk space is insufficient, and you need to add other disk
CPU resources are too high.
The ADOM disk quota is set too low based on log rates
Logs in that ADOM are being forwarded in real-time to another FortiAnalyzer device.
For proper log correlation between the logging devices and FortiAnalyzer, FortiAnalyzer and all registered devices should:
Use DNS
Use host name resolution
Use real-time forwarding
Use an NTP Server
How can you configure FortiAnalyzer to permit administrator logins from only specific locations?
Use static routes
Use administrative profiles
Use trusted hosts
Use secure protocols
On FortiAnalyzer, what is a wildcard administrator account?
An account that permits access to members of an LDAP group
An account that allows guest access with read-only privileges
An account that requires two-factor authentication
An account that validates against any user account on a FortiAuthenticator
For which two purposes would you use the command act log checkout? (Choose two)
To encrypt log communications
To help protect against man-in-the middle attacks during log upload from FortiAnalyzer to an SFTP server
To send an identical set of logs to a second Iogging server
To prevent log modification or tampering
What is the purpose of a dataset query In FortiAnalyzer?
It extracts the database schema
It injects log data into the database
It sorts log data into tables
It retrieves log data from the database
Which two of the following must you configure on FortiAnalyzer to email a FortiAnalyzer report externąlly? (Choose two)
SFTP server
Which log type does the FortiAnalyzer indicators of compromise feature use to identity infected hosts?
Application control logs
Antivirus logs
Web filter logs
IPS logs
Which clause is considered mandatory in SELECT statements used by the FortiAnalizer to generate
FROM
LIMIT
WHERE
ORDER BY
You have recently grouped multiple FortiGate devices into a single ADOM. System Settings > Storage info shows the quota used. What does the disk quota refer to?
The maximum disk utilization for the FortlArialyzer model
The maximum disk utilization for each device in the ADOM
The maximum disk utilization for the ADOM type
The maximum disk utilization for all devices in the ADOM
Refer to the exhibit. What does the data point at 14:55 tell you?
Raw logs are reaching FoniAnalyzer faster than they can be indexed.
Logs are being dropped
The Splurged daemon is behind in log indexing by two logs
The received rate is almost at its maximum for this device
Which two settings must you configure on FortiAnalyzer to allow non-local admintstrotors to authenticate to FortiAnalyzer with any user account in single LDAP group? (Choose two)
A trusted host profile that restricts access to the LDAP group
An administrator group.
A remote LDAP server.
A local wildcard administratar account.
FortiAnalyzer reports are dropping analytcal data from 16 days ago, even though the data policy setting for analytics logs is 60 days
What is the most filely problem?'
Quota enforcement is acting on analytical data before a report is complete
Disk utilization for archive logs is set for 15 days
Logs are rolling before the report is run.
You need to upgrade your FortiAnalyZer firmware. Wnat happens to the logs being sent to FortiAnalyzer from FotiiGate during the lime FortiAnalyzer is temporarily unavailable?
FortiAnalyzer uses log fetching to relieve the logs when back online.
FortiGate uses the miglogd process to cache the logs.
The logfled process stores logo in offline mode
Logs are dropped
After you have moved 3 registered logging device out of one ADOM and into a new ADOM, what is the purpose of running the following CLI command? execute sql-local rebuild-adorn < new -ADOM-name>
To remove the analytics logs of the device from the old database.
To migrate the archive logs to the new ADOM
To populate the new ADOM with analytical logs for the moved device, so you can run reports.
To reset the disk quota enforcement to default
You are using RAID with a FortiAnolyzer that supports software RAID and one of the hard disks on FortiAnalyzer has failed. What is the recommended method to replace the disk?
Clear all RAID alarms and replace the disk while FortiAnatyzer is still running.
Perform a hot swap
Downgrade your RAID level, replace the disk, and then upgrade your RAID level
Shut down FortiAnaIyzer and then replace the disk.
Why should you use an NTP server on FortiAnalyzer and all registered devices that log into FortiAnaIyzer?
To resolve host names
To use real-time forwarding
To properly correlate logs
To improve DNS response times